Man jailed for over 5 years and fined $76K for selling VPN in southern China
scmp.com
scmp.com
Root certificates aren't useful either unless users install them. On the other hand, private keys of SSL providers can be of use for serving false certificates, but that's only useful if you also MITM.
As of writing this message I currently have over 170 root certificates on my macOS. Some of them are from companies who are known to care very little about your privacy. There's even a "Federal Common Policy" certificate which is actually run by the US government [1]
If the government did MITM you're traffic, it would still show in the certificate chain. But how many people really check this every time they visit a site?
2. Regardless, Certificate Transparency means it will almost certainly be noticed.
The GFW have the ability to detect VPN connections and you will got a connection reset...It’s more and more difficult to use blocked service/site in china.
VPNs are becoming obsolete, Proxies like ShadowsocksR are still usable.
AFAIK AWS, DigitalOcean, GCP are regularly blocked. GigsGigs in HK is throttled.
GFW even blacklisted my personal domain because I was running DNS queries against it to establish my SS tunnel. At least it seems like it.
This is also quite different from (some?) Islamic states where sites are generally whitelisted. With GFW everything is allowed until it's blacklisted.
Interesting. I am wondering how they update their posts. Because scmp.com is actually being blocked in where I am staying at. Maybe some state sanctioned services? I have been using aliyun services and never had any issues.. yet..
SCMP is completely inaccessible from China Unicom (mobile) and China Telecom (landline). Most possible the other options also block it.